Privacy Policy
Last updated: 24 February 2025
1. Who we are
ParentKit is operated by Multiordinal Limited, a company registered in the United Kingdom. When we say "we", "us", or "our", we mean Multiordinal Limited.
ParentKit is an AI-powered coordination service for parents. It helps you stay on top of family schedules, tasks, and information without the mental load.
2. What we collect
We collect only what is needed to provide the service:
- Account information – your email address, name, and timezone when you sign up.
- Email content – when you connect an email account, we access emails to scan for family-related events. Email content is cached temporarily and encrypted at rest.
- OAuth tokens – stored securely so we can access your email on your behalf. Refresh tokens are encrypted.
- Events and tasks – events extracted from emails and tasks you create or import.
- Brain entries – facts and notes you store in the Brain feature.
- Preferences and settings – timezone, notification preferences, reminder offsets.
- Telegram chat ID – if you connect Telegram for notifications.
- Push notification endpoints – if you enable browser push notifications.
- Sender rules – your whitelist and blacklist choices for email filtering.
- Connections and shares – when you connect with other ParentKit users and share tasks or thoughts.
- IP addresses – used only for rate-limiting login attempts. Not stored long-term or used for tracking.
3. How we use your data
Your data is used solely to provide and improve the ParentKit service:
- Email scanning – we read your emails to extract family-related events like school dates, appointments, and deadlines.
- AI event extraction – email content is sent to Google's Gemini AI to identify events. See "Third-party services" below.
- Reminders and notifications – we send you reminders via Telegram or browser push at the times you choose.
- Task management – we store and manage tasks, subtasks, and notes you create.
- Sharing – when you share tasks or brain entries with connected users, we make that content visible to them.
- Brain queries – when you ask the Brain a question, we use AI to search your stored facts for an answer.
4. Third-party services
ParentKit integrates with the following services to function:
- Google Gmail API – to read your emails and extract events. Access is governed by your OAuth consent and can be revoked at any time.
- Google Gemini AI – to extract events from email content and power Brain queries. Your data sent to Gemini is not used by Google to train AI models (per Google's API data usage policies).
- Telegram Bot API – to send you notifications and process messages you send to the bot.
- Web Push – to deliver browser push notifications if you enable them.
- SendGrid – to send magic link login emails. Only your email address is shared.
5. What we don't do
- We do not sell your data to anyone, ever.
- We do not show advertising.
- We do not use web tracking, analytics cookies, or fingerprinting.
- We do not train AI models on your data. Your content is processed by AI only to provide features you use.
- We do not share your data with third parties beyond the service integrations listed above.
6. Data security
We take the security of your data seriously:
- Email content is encrypted at rest using AES-256-GCM.
- OAuth tokens and IMAP passwords are stored with encryption.
- Personally identifiable information is masked in application logs.
- Sessions are encrypted and secured with HTTP-only cookies.
- Login attempts are rate-limited and magic link codes are protected against brute-force attacks.
7. Data retention
- Email cache – retained until you disconnect the email account or delete your account.
- Deleted tasks – soft-deleted and retained for 30 days before permanent removal, so you can restore them if needed.
- Magic link codes – expire after 10–15 minutes and are single-use.
- Account data – retained until you choose to delete your account. When you delete your account, all your data is permanently removed.
8. Your rights
You can:
- Access your data – everything you've stored is visible in the app.
- Delete your account – from the Settings page. This permanently removes all your data.
- Disconnect email accounts – revoke access at any time from Settings or from your Google account.
- Contact us – email privacy@parentkit.co.uk with any questions or requests about your data.
If you are in the UK or EU, you also have the right to lodge a complaint with your local data protection authority.
9. Children's privacy
ParentKit is designed for parents and guardians. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to this policy
We may update this policy from time to time. If we make significant changes, we will notify you through the app or via your connected messaging channel. Continued use of ParentKit after changes constitutes acceptance of the updated policy.
11. Contact
If you have any questions about this privacy policy or how we handle your data:
Multiordinal Limited
Email: privacy@parentkit.co.uk